Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a security incident from the Security Incident list

In addition to automatic methods for creating security incidents, you can create them manually, as needed.

This video shows a visual overview of how you could create a security incident from the Security Incident list.

Before you begin

Role required: sn_si.basic

Procedure

  1. Navigate to any security incident list (for example, All > Security Incident > Incidents > Show All Incidents).

  2. Select New.

  3. On the form, fill in the fields.

FieldDescription
Select security tagIf needed, select a Security tag to add metadata to the record or identify who should have access to this security incident record. This field appears only after the security incident has been saved.Note: Manual tags are preserved when automatic tags are applied.
Number\[Read only\] The security incident number.
Requested byThe person requesting the work to be performed.
Configuration ItemThe server, computer, router, or other configuration item affected by the security issue.
Affected userThe person affected by the security issue.
LocationThe location of the requester or resource. If a Configuration Item is not selected, this field is pre-filled with the location of the requester.
Category

The category that identifies the type of security issue.If a category is selected, a workflow for analyzing this issue is executed when the record is saved. For example, if you select Denial of Service, the Security Incident - Denial of Service - Template workflow is executed.

For more information, see Security Incident Response workflow templates.

SubcategoryThe subcategory that further defines the issue.
Opened\[Read only\] Displays the date and time the incident was opened.
StateThe current state of the security incident. Upon security incident creation, this field defaults to Draft.
SubstateIdentifies whether the security incident includes a pending problem or change.
SourceIdentifies the source of the security incident, such as email, a phone call, or network monitoring.
Alert SensorSecurity integration through which you ingest the alert or event data such as CarbonBlack, CrowdStrike, McAfee, and so on.
Alert RuleThe rule in the security product which triggered the creation of this security incident.
Risk score

Displays the risk score calculated for this security incident. The value is based on the priority of the security incident, the type of security incident (Denial of Service, Spear Phishing, or Malicious code activity), and the number of sources that triggered a failed reputation score on an indicator. The risk score aids in prioritizing security incident work for analysts. Three security incident properties enable you to further designate a color-coded dot to appear next to the risk score in list view to make them more easily identifiable.

If you change certain fields in the security incident, such as the Business impact or Priority, and save the record, the Risk score is automatically recalculated and displayed. The change is also reflected in the work notes and on the Risk Score Audits related list.

Note: The risk score is also recalculated when affected users are associated with a security incident, affected services, or vulnerable items.

You can also manually enter a new Risk score. This can be useful if you want to keep a particular security incident at the top of the list of security incidents you are analyzing. If you enter a new Risk score, the Risk score override check box is automatically selected. Regardless of the changes made in the security incident, a manually-entered risk score is not automatically recalculated.

Note: If you have upgraded your instance from a prior release, risk scores were calculated for all of your open security incidents. For more information, see Understanding security incident calculators.

Risk score overrideSelect this check box to override the automatic update of the risk score. The override is reflected in the work notes.
Business impactSelect the importance of this security incident to your business. The default value is Non-critical. If, after the security incident record has been saved, you change the value in the Priority fand/or Risk fields, the Business impact is recalculated.
PrioritySelect the order in which to address this security incident, based on the urgency. If this value is changed after the record is saved, it can affect the Business impact calculation.
Assignment groupThe group to which this security incident is assigned.
Assigned toThe individual assigned to analyze this security incident. Assignments can be performed manually or automatically. For more information, see Assigning security analysts.
Short descriptionA brief description of the security incident.
Knowledge resultsAs you type the short description, links to related articles from the knowledge base appear. Scanning the information could solve your issue.
  1. Select and hold (or right-click) in the record header and select Save.

    If you added a new CI to the security incident, the following integration workflows are automatically executed:

    Note: Additional workflows are executed based on the third-party integrations you have activated as follows Security Operations Carbon Black Integration - Get Running Processes Flow

Related topics

Security Incident Response setup